-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Wed, 17 Sep 2025 22:25:31 -0400
Source: chromium
Architecture: source
Version: 140.0.7339.185-1~deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
chromium (140.0.7339.185-1~deb13u1) trixie-security; urgency=high
.
* New upstream security release.
- CVE-2025-10585: Type Confusion in V8.
Reported by Google Threat Analysis Group.
- CVE-2025-10500: Use after free in Dawn.
Reported by Giunash (Gyujeong Jin).
- CVE-2025-10501: Use after free in WebRTC. Reported by sherkito.
- CVE-2025-10502: Heap buffer overflow in ANGLE.
Reported by Google Big Sleep.
Checksums-Sha1:
4ee38f18fb4014e6dd7ff1da7f1a14cee7f765f6 4027 chromium_140.0.7339.185-1~deb13u1.dsc
9965e95aba521ca0a6bcb1861106ad33f1f2ee50 993761236 chromium_140.0.7339.185.orig.tar.xz
f535faa89466fa5baff46d050a57b5dafce58e46 413828 chromium_140.0.7339.185-1~deb13u1.debian.tar.xz
e2eada0918946d738b9616ef5c4354ab110d3f17 26325 chromium_140.0.7339.185-1~deb13u1_source.buildinfo
Checksums-Sha256:
bb1477fa3bdd049bc89840aa0c1ab9d5cfb87c4f711580276c716b7678c03626 4027 chromium_140.0.7339.185-1~deb13u1.dsc
f81f22c5d544c2a62df83bf2608e98d8ef822ed8cdc359ae805a8ed9e7549873 993761236 chromium_140.0.7339.185.orig.tar.xz
275a5c8af1849c06241233d3afc73b347235e4645f3be2753d29eb29ad8c2251 413828 chromium_140.0.7339.185-1~deb13u1.debian.tar.xz
d748ae0473d842a6da4d7fdd6f47c8b6f80ebf77db0f9692308eacefc32520c1 26325 chromium_140.0.7339.185-1~deb13u1_source.buildinfo
Files:
fea6f8c16db07c7ae62177b5b0ea58ae 4027 web optional chromium_140.0.7339.185-1~deb13u1.dsc
2e4618786d6a135df98a5106b59fba32 993761236 web optional chromium_140.0.7339.185.orig.tar.xz
200b8a8576fc5a497645fd04b122fc98 413828 web optional chromium_140.0.7339.185-1~deb13u1.debian.tar.xz
e094764dc59f74d3a17e9e780ee9da0c 26325 web optional chromium_140.0.7339.185-1~deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmjMPwMUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjeXWA/9HSDGhZnXBARRx7B5M9BuxSXnSZm6
JZMQw0sW4AftyGO8lIzGY3tmbUH7snf1Lh4+dAXngM9nuOZknB3KqwMr7RBIZrVg
AthFwu5IxjsqPpsmVjpxjRiK6E1Qbs7ltx6MBAeyWcRBg2eU8IUypfplZNWG+/ZU
mi9AIcgvbxXPeYlaXYbgeBMj8x5oBNI0edybdkHRnNdbESNQeNXbbDtT9qIhOy0Y
nQYwAtJS6FUMRD1DJH26SRSTkbaiHHrLP4CoPyic2C4GewotIcXoyXK1F/duiQx9
vyerS78o3Xi+YJ3CMYVJm0C1RxBktR1KIinHTIcmvpaay+52JswaJ6PMHGTPeyCN
3UkiH6X/ZVtcNCVSn/cEcyHpjy0efcGFVF1ZFVLQgt8MTn2pVwSHetZPhr+tt2oU
SNLkXIQ+j2AIbX6znpNwpNYRTFr6+BP46buZV7qCkfGxh25QiZnoUiJDTTIQMlMF
hOQJPg7dizeu+kQ1oPryWu6CCE3z5qv24GUF+qfYLTqtB3gobr5buyChhPBk9SBI
5EZqRfS3HBYArpP9Vi3O66+JPmz5irNpnBe+6SETAi8ux0q0P/aw0xo3i2nIW8kR
x6GzYa8eHHF9iqY8cjMsDgnwOCpUuPPwP1zFdKfdwc8+bSMW9Nb5FAPpZ+0TRQu8
31qJzOQf6aZtJrc=
=77+5
-----END PGP SIGNATURE-----